Cisco TelePresence Software before TE 4.1.1 on the Cisco IP Video Phone E20 has a default password for the root account after an upgrade to TE 4.1.0, which makes it easier for remote attackers to modify the configuration via an SSH session, aka Bug ID CSCtw69889, a different vulnerability than CVE-2011-2555.
References
Link | Resource |
---|---|
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120118-te | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2012-01-19 07:55
Updated : 2012-02-09 21:00
NVD link : CVE-2011-4659
Mitre link : CVE-2011-4659
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
cisco
- ip_video_phone_e20
- telepresence_e20_software